Security Advisory Desk
highQCS priority 100/100Cisco

Cisco Finesse Server-Side Request Forgery Vulnerability

Cisco Finesse, a web-based management tool used in contact center environments, has a vulnerability that lets attackers trick the server into sending unauthorized requests. This vulnerability exists because the system doesn't properly check certain incoming web requests. Attackers can exploit this by sending specially crafted HTTP requests, potentially revealing some sensitive information related to the services running on the device. Cisco is working on software updates to fix this issue, but currently, there are no temporary workarounds available.

QCS published 8/10/2026, 8:51:43 am ISTVendor disclosure 7/10/2026, 9:30:00 pm ISTVerified 8/10/2026, 8:51:43 am ISTRevision 1

In plain language

What this advisory means

Cisco Finesse, a web-based management tool used in contact center environments, has a vulnerability that lets attackers trick the server into sending unauthorized requests. This vulnerability exists because the system doesn't properly check certain incoming web requests. Attackers can exploit this by sending specially crafted HTTP requests, potentially revealing some sensitive information related to the services running on the device. Cisco is working on software updates to fix this issue, but currently, there are no temporary workarounds available.

Technical explanation

How the issue affects the environment

The Cisco Finesse web-based management interface is susceptible to a server-side request forgery (SSRF) vulnerability due to improper input validation of specific HTTP requests. An unauthenticated, remote attacker can exploit this vulnerability by crafting and sending malicious HTTP requests that cause the affected device to initiate unauthorized requests. Successful exploitation could allow disclosure of limited sensitive information about services associated with the device. This impacts Cisco Finesse and related products such as Packaged Contact Center Enterprise, Unified Contact Center Enterprise, and Unified Contact Center Express. Cisco has assigned CVE-2026-20362 and rated the severity as high with a CVSS base score of 7.2. Software updates fixing the vulnerability are planned for Cisco Finesse 15.0(1)SU3 and respective product releases scheduled for early 2027. No effective workarounds exist, making software upgrade the only viable remediation.

Operational impact

Why teams should care

Organizations using Cisco Finesse and related contact center products risk unauthorized disclosure of sensitive service-related information. This exposure can lead to further security compromise, operational disruption, or targeted attacks. Given the lack of workarounds, affected businesses must plan timely software updates to remediate the vulnerability, ensuring continued confidentiality and integrity of their contact center operations.

Immediate action

Cisco strongly recommends upgrading affected Cisco Finesse and related product installations to the designated fixed software releases as soon as they become available. Customers should confirm hardware and software compatibility prior to upgrade and verify vulnerability mitigation post-upgrade. Due to no available workarounds, patching is the primary remediation measure.

Affected and fixed releases

Affected versionsCisco Finesse 12.6 and earlier, Packaged CCE earlier than 15.0, Unified CCE earlier than 15.0, Unified CCX 12.5 and earlier
Fixed versionsCisco Finesse 15.0(1)SU3 (Feb 2027), Packaged CCE/Unified CCE 15.0(1)ES202701 (Jan 2027), Unified CCX 15.0(1)SU2 (Feb 2027)

Temporary risk reduction

Cisco states there are no workarounds that address this vulnerability. Temporary mitigations and partial workarounds are insufficient until fixed software is deployed.

Evidence and validation checklist

  • Cisco official security advisory published 2026-10-07
  • Advisory states SSRF vulnerability due to improper input validation
  • Vulnerability affects Cisco Finesse and related contact center products
  • No workarounds available
  • Planned fixes with release versions and schedule provided
  • No reports of active exploitation
  • Severity rated High, CVE-2026-20362 assigned

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source